Security authentication method and device compatible with multiple operating systems
By providing a secure authentication method with strong compatibility in a multi-operating system environment, the problem of discrete authentication methods and management difficulties in coexistence scenarios of multiple operating systems is solved, and unified authentication and centralized management are realized, and security and management efficiency are improved.
Patent Information
- Application Number
- CN202311511579.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-13
- Publication Date
- 2025-05-13
AI Technical Summary
In office scenarios where multiple operating systems coexist, the existing technology has problems such as discrete authentication methods, difficulty in management, low digitalization level and low security.
It provides a security authentication method that is compatible with multiple operating systems, including receiving network authentication packets from different operating system terminals, parsing and converting them into unified authentication packets, performing identity and permission authentication, group management, and network access control based on the firewall and security policies of the packet.
It realizes unified security authentication and centralized management of each operating system terminal, reduces the difficulty of security authentication management of different operating systems, improves the timeliness and accuracy of network access, enhances the rationality of network access control, and avoids information leakage and resource waste.
Smart Images

Figure CN119995909A_ABST
Abstract
Description
Technical Field
[0001] This article relates to the fields of security prevention and control and information security, and can be used in the field of financial technology. In particular, it relates to a security authentication method and device that is compatible with multiple operating systems. Background Art
[0002] With the development of terminal technology, there are a variety of emerging operating systems (such as Tongxin UOS, Kylin and other operating systems) and traditional Windows operating system terminals coexist in office modes. While facilitating users to choose from multiple options, it also brings the following practical problems:
[0003] There are various types of network access authentication messages. Currently, each operating system has its own independent authentication module. When multiple operating systems coexist, it is necessary to configure an authentication module for each operating system, which results in high resource consumption and high management costs. In addition, after the authentication is passed, network access control is not performed without distinguishing users, resulting in unreasonable network access control, which can easily lead to information leakage or waste of resources for network access control.
[0004] In the scenario of complex operating systems running in parallel, higher requirements are placed on safe office work, such as whether there is virus infringement, whether there is unauthorized software, whether the message transmission is compliant and legal, etc., and there is a lack of a unified monitoring and alarm mechanism;
[0005] Offices using multiple operating systems lack centralized monitoring and deployment of key performance indicators such as user online behavior and system availability. Summary of the invention
[0006] This article aims to solve the problems in the existing technology of discrete authentication methods in multi-operating system parallel office scenarios, difficult management, and low digitization and security levels.
[0007] In order to solve the above technical problems, this paper provides a security authentication method compatible with multiple operating systems, the method comprising:
[0008] Receive network access authentication messages sent by terminals with different operating systems;
[0009] Parse the network access authentication messages sent by each operating system terminal and convert them into a unified authentication message;
[0010] Perform identity authentication and authority authentication according to the unified authentication message;
[0011] Group the terminals that have passed identity and authority authentication;
[0012] The terminal's access to the network is controlled based on the firewall and security policy of the group to which the terminal belongs.
[0013] As a further embodiment of this invention, the multi-operating system compatible security authentication method further includes:
[0014] After the terminal successfully accesses the network, the network access time of the user using the terminal is recorded;
[0015] Calculate the network access time of each operating system used by the user based on the network access time of each terminal and the operating system installed on each terminal;
[0016] Calculate usage information of each operating system based on the network access time of each operating system used by the user;
[0017] Generate operating system purchase recommendations based on the usage information of each operating system.
[0018] As a further embodiment of this invention, the multi-operating system compatible security authentication method further includes:
[0019] Get the terminal network access log;
[0020] Extract behavioral keyword information from network access logs;
[0021] Match the behavior keyword information with the blacklist database. If the match is successful, an abnormal alarm is issued. The blacklist database includes unauthorized software information and virus information.
[0022] The number of behavior keyword information within the preset time window is counted, and when the number is greater than the preset value, an abnormal alarm is issued.
[0023] As a further embodiment of this invention, the multi-operating system compatible security authentication method further includes:
[0024] According to the number of abnormal alarms of each terminal, count the number of abnormal times users use each operating system;
[0025] Count the total number of times users use each operating system;
[0026] Calculate the violation index of the user's use of each operating system according to the abnormal number of times the user uses each operating system and the total number of times the user uses each operating system;
[0027] Based on the violation indicators of users using each operating system, recommendation information for users to use the operating system is generated.
[0028] As a further embodiment of this invention, the multi-operating system compatible security authentication method further includes:
[0029] Obtaining usage information of each terminal operating system, wherein the usage information of the terminal operating system includes: startup time, resource usage information, crash information, software information, research information and network access time information;
[0030] Analyze the usage information of each terminal operating system and determine multiple dimensional evaluation indicators of each terminal operating system;
[0031] According to the multiple dimensional evaluation indicators of each terminal operating system, the multi-dimensional evaluation indicators of each operating system are calculated;
[0032] Determine the availability of the operating system based on the evaluation indicators of multiple dimensions of each operating system;
[0033] Generate operating system purchase recommendations based on operating system availability.
[0034] As a further embodiment of this invention, the usage information of each terminal operating system is analyzed to determine multiple dimensional evaluation indicators of each terminal operating system, including:
[0035] Calculate the startup time score of the terminal operating system according to the startup time of the terminal operating system;
[0036] Calculate the resource usage score of the terminal operating system based on the terminal operation resource usage information;
[0037] Calculate the stability score of the terminal operating system based on the terminal operation crash information;
[0038] Calculate the compatibility score of the terminal operating system based on the terminal operating software information;
[0039] The usability score of the terminal operating system is calculated based on the terminal operation survey information and network access time information.
[0040] As a further embodiment of this invention, according to the evaluation indicators of multiple dimensions of each operating system, determining the availability of the operating system includes calculating the availability of the operating system using the following formula:
[0041] U i =w1×P i +w2×R i +w3×S i +w4×L i +w5×C i ;
[0042] Among them, U i Score the usability of operating system i, P i Score the startup time of operating system i, R i Score the resource usage of operating system i, S i is the stability score of operating system i, L i Score the usability of operating system i, C i is the compatibility score of operating system i, w1, w2, w3, w4 and w5 are the weights of the corresponding indicators.
[0043] A second aspect of the present invention provides a security authentication device compatible with multiple operating systems, the device comprising:
[0044] A receiving unit, used to receive network access authentication messages sent by terminals of different operating systems;
[0045] A conversion unit, used to parse the network access authentication message sent by each operating system terminal and convert it into a unified authentication message;
[0046] An authentication unit, used to perform identity authentication and authority authentication according to the unified authentication message;
[0047] A grouping unit, used to group terminals that have passed identity and authority authentication;
[0048] The control unit is used to control the network access of the terminal according to the firewall and security policy of the group to which the terminal belongs.
[0049] A third aspect of the present invention provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in any of the foregoing embodiments when executing the computer program.
[0050] A fourth aspect of the present invention provides a computer storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor of a computer device, implements the method described in any of the foregoing embodiments.
[0051] The multi-operating system compatible security authentication method and device provided in this article convert the network authentication messages sent by different operating system terminals into a unified authentication mode, so that a network authentication module installed on the security authentication server can realize the unified security authentication and centralized management of each operating system terminal, ensure the timeliness and accuracy of network access, and reduce the difficulty of security authentication management of different operating systems. Through the network access control of user groups, personalized control of user network access can be achieved, the rationality of network access control can be increased, and the problem of information leakage or network access control consuming resources can be avoided. At the same time, it can also facilitate the statistics of user behavior in each group and provide a basis for the behavior norms of each group of users.
[0052] In order to make the above and other purposes, features and advantages of this article more obvious and easy to understand, the following specifically cites preferred embodiments and describes them in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] In order to more clearly illustrate the technical solutions in the embodiments of this article or the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of this article. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0054] Figure 1 A first flow chart of a multi-operating system compatible security authentication method according to an embodiment of the present invention is shown;
[0055] Figure 2 A second flow chart of the multi-operating system compatible security authentication method of the embodiment of this document is shown;
[0056] Figure 3 A third flow chart of the multi-operating system compatible security authentication method of the embodiment of this document is shown;
[0057] Figure 4 A fourth flow chart of the multi-operating system compatible security authentication method of the embodiment of this document is shown;
[0058] Figure 5 A fifth flow chart of the multi-operating system compatible security authentication method of the embodiment of this document is shown;
[0059] Figure 6 A structural diagram of a multi-operating system compatible security authentication device according to an embodiment of this document is shown;
[0060] Figure 7 The structure diagram of the network access authentication module in the embodiment of this article is shown;
[0061] Figure 8 A structural diagram of a computer device according to an embodiment of this invention is shown.
[0062] Description of the accompanying symbols:
[0063] 601, network access authentication module;
[0064] 602, monitoring module;
[0065] 701, receiving unit;
[0066] 702, conversion unit;
[0067] 703, authentication unit;
[0068] 704, grouping unit;
[0069] 705. Control unit;
[0070] 802. Computer equipment;
[0071] 804, processor;
[0072] 806. Memory;
[0073] 808, driving mechanism;
[0074] 810, input / output module;
[0075] 812. Input device;
[0076] 814. Output device;
[0077] 816. Presentation equipment;
[0078] 818. Graphical user interface;
[0079] 820, network interface;
[0080] 822, communication link;
[0081] 824. Communication bus. DETAILED DESCRIPTION
[0082] The following will be combined with the drawings in the embodiments of this article to clearly and completely describe the technical solutions in the embodiments of this article. Obviously, the described embodiments are only part of the embodiments of this article, not all of the embodiments. Based on the embodiments of this article, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this article.
[0083] It should be noted that the terms "first", "second", etc. in the specification and claims of this article and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of this article described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, device, product or equipment that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0084] This specification provides method operation steps as described in the embodiments or flow charts, but more or fewer operation steps may be included based on routine or non-creative work. The order of steps listed in the embodiments is only one way of executing the order of many steps and does not represent the only execution order. When the system or device product is executed in practice, it can be executed in the order of the method shown in the embodiments or the drawings or in parallel.
[0085] It should be noted that the security authentication method and device compatible with multiple operating systems in this article can be used in the financial field, and can also be used in any field other than the financial field. The application field of the security authentication method and device compatible with multiple operating systems in this article is not limited.
[0086] In the existing office environment, there are scenarios where terminals with different operating systems coexist, and these operating system terminals need to be authenticated by the corresponding authentication module in the security authentication server before they can be used. Therefore, when multiple operating systems coexist, since authentication modules need to be configured for each operating system, there are problems of high resource consumption and high management costs for authentication modules. In addition, after authentication, network access control is not performed without distinguishing users, resulting in unreasonable network access control, which is prone to information leakage or resource consumption of network access control. In addition, for scenarios where multiple operating systems coexist, there is a lack of centralized monitoring and deployment of key assessment indicators such as user online behavior and system availability.
[0087] In order to solve the above technical problems, this paper provides a security authentication method compatible with multiple operating systems, which is applied to a security authentication server compatible with multiple operating systems. The security authentication server is connected to terminals with different operating systems, such as Figure 1 As shown, the security authentication method compatible with multiple operating systems includes:
[0088] Step 101, receiving network access authentication messages sent by terminals of different operating systems;
[0089] Step 102, parsing the network access authentication message sent by each operating system terminal and converting it into a unified authentication message;
[0090] Step 103, performing identity authentication and authority authentication according to the unified authentication message;
[0091] Step 104, grouping the terminals that have passed identity and authority authentication;
[0092] Step 105: Control the network access of the terminal according to the firewall and security policy of the group to which the terminal belongs.
[0093] In detail, the operating systems involved in step 101 include but are not limited to Tongxin UOS, Kylin, Windows operating system, etc. The network access authentication message corresponding to each operating system includes fields such as authentication number, MAC address, device serial number, user information, certificate information, etc., where user information includes user role, account information, etc. The network access authentication messages of different operating systems also include other fields, and the positions of the same fields in the network access authentication messages of different operating systems may be different.
[0094] In step 102, the program for parsing the network access authentication message sent by each operating system terminal is provided by each operating system, and converting the data parsed by each operating system into a unified authentication message includes: determining the operating system identifier according to the sending device of the network access authentication message; determining the parsing program of the network access authentication message according to the operating system identifier, and the parsing program of the network access authentication message parses the network access authentication message; and converting the parsed data into a unified authentication message using a preset template. The field order in the unified authentication message is, for example, a unified authentication number, a MAC address, a device serial number, user information, and an operating system identifier.
[0095] Step 103: identity authentication according to the unified authentication message includes: using the device serial number and user information to authenticate the device identity and user identity respectively. Permission authentication according to the unified authentication message includes: unified authentication number authentication and user permission level confirmation.
[0096] The basis for grouping the terminals in step 104 includes: grouping the terminals according to different user rights, and users with different rights include but are not limited to temporary, permanent, external personnel, etc.
[0097] Step 105 configures firewalls and security policies for different groups of users in advance, and uses the pre-configured firewalls and security policies and the groups to which the terminals belong to determine the firewalls and security policies, thereby controlling the network access of the terminals.
[0098] This embodiment converts the network access authentication messages sent by different operating system terminals into a unified authentication mode through steps 101 to 103, so that by installing a network access authentication module on the security authentication server, unified security authentication and centralized management of each operating system terminal can be achieved, ensuring the timeliness and accuracy of network access and reducing the difficulty of security authentication management of different operating systems.
[0099] This embodiment controls user group access to the network through steps 104 and 105, which can achieve personalized control of user access to the network, increase the rationality of network access control, avoid information leakage or waste of resources for network access control, and at the same time, facilitate statistics on the behavior of each group of users, providing a basis for the behavior norms of each group of users.
[0100] In one embodiment of this invention, Figure 2 As shown, the security authentication method compatible with multiple operating systems also includes:
[0101] Step 201, after the terminal successfully accesses the network, the network access time of the user using the terminal is recorded;
[0102] Step 202, calculating the network access time of each operating system used by the user according to the network access time of each terminal used by the user and the operating system installed on each terminal;
[0103] Step 203, calculating usage information of each operating system according to the network access time of each operating system used by the user;
[0104] Step 204: Generate operating system purchase suggestions based on the usage information of each operating system.
[0105] When step 201 is implemented, after the terminal successfully accesses the network, a timer is allocated and started for the terminal, and the timer records the network access time of the user using the terminal.
[0106] When step 202 is implemented, the network access time of the user using each terminal recorded in the predetermined time period of step 201 is first grouped according to the operating system installed on the terminal to obtain the network access time group of each operating system. The network access time group of each operating system includes the network access time data of the terminal of each operating system. For example, the devices corresponding to operating system A include device 1, device 2 and device 3, then the network access time group of operating system A includes the network access time of device 1, the network access time of device 2 and the network access time of device 3; then the data in the network access time group of each operating system is added and calculated to obtain the network access time of the user using each operating system.
[0107] In step 203, the usage information of each operating system includes the usage rate of each operating system. The usage rate of each operating system is obtained by dividing the network access time of each operating system by the total network access time of all operating systems.
[0108] When step 204 is implemented, the top N operating systems ranked by usage rate may be screened out to generate purchase suggestions, where N is a positive integer.
[0109] This embodiment can provide a basis for operating system procurement by monitoring the network access time of each operating system, thereby enabling decision makers to purchase an operating system that meets the actual needs of users and reduce the impact of human factors.
[0110] In one embodiment of this invention, Figure 3 As shown, the security authentication method compatible with multiple operating systems also includes:
[0111] Step 301, obtaining the terminal network access log;
[0112] Step 302, extracting behavior keyword information from the network access log;
[0113] Step 303, matching the behavior keyword information with the blacklist database, and if the match is successful, issuing an abnormal alarm, wherein the blacklist database includes unauthorized software information and virus information;
[0114] Step 304: Count the number of identical behavior keyword information within a predetermined time window, and issue an abnormal alarm when the number is greater than a predetermined value.
[0115] When step 301 is implemented, each terminal network access log can be directly obtained from the log library of the security authentication server.
[0116] The behavior keyword information in step 302 includes information about calling software, visiting website, etc.
[0117] The predetermined time window in step 304 can be determined according to the actual abnormal tolerance, and the specific value thereof is not limited in this document. The predetermined time window setting can eliminate the false touch situation and ensure the accuracy of the abnormal alarm.
[0118] This embodiment can timely discover abnormal behavior of users and issue an alarm in time by analyzing the network access log.
[0119] In one embodiment of this invention, Figure 4 As shown, the security authentication method compatible with multiple operating systems also includes:
[0120] Step 401, counting the number of abnormal times when users use each operating system;
[0121] Step 402, counting the total number of times the user uses each operating system;
[0122] Step 403, calculating the violation index of the user using each operating system according to the abnormal number of times the user uses each operating system and the total number of times the user uses each operating system;
[0123] Step 404: Generate suggestion information for the user to use the operating system based on the violation indicators of the user using each operating system.
[0124] Specifically, what is counted in step 401 and step 402 is the number of abnormal times that users use each operating system within a predetermined time interval and the total number of times that users use each operating system. The predetermined time interval can be set according to actual needs, and this document does not specifically limit its value.
[0125] Step 403 calculates the violation index of the user using each operating system by dividing the number of abnormal times the user uses each operating system by the total number of times the user uses each operating system. The violation index of the user using each operating system reflects the user's proficiency in the operating system and the operating rules. The larger the violation index value, the lower the proficiency in the operating system and the greater the operating risk. Based on this, recommendation information for the user to use the operating system can be generated. For example, when the violation index of a user for a certain operating system is greater than the violation threshold, recommendation information for training the user to use the operating system is generated.
[0126] This embodiment can provide a basis for regulating the user's behavior in using the operating system by counting the abnormal number of times the user uses each operating system.
[0127] In one embodiment of this invention, Figure 5 As shown, the security authentication method compatible with multiple operating systems also includes:
[0128] Step 501, obtaining usage information of each terminal operating system, wherein the usage information of the terminal operating system includes: startup time, resource usage information, crash information, software information, research information and network access time information;
[0129] Step 502, analyzing the usage information of each terminal operating system to determine multiple dimensional evaluation indicators of each terminal operating system;
[0130] Step 503, calculating a multi-dimensional evaluation index of each operating system according to the multi-dimensional evaluation indexes of each terminal operating system;
[0131] Step 504, determining the availability of the operating system according to the evaluation indicators of multiple dimensions of each operating system;
[0132] Step 505: Generate an operating system purchase suggestion based on the availability of the operating system.
[0133] Specifically, when step 501 is implemented, the startup time, resource usage information, crash information and software information in the usage information are obtained by embedding points in the terminal. The survey information is obtained through online or offline questionnaires, and the network access time information is obtained by analyzing the security authentication server.
[0134] Specifically, the boot time refers to the time from when the operating system is booted to when it is available for use. The shorter the boot time of the operating system is, the better the availability of the operating system is.
[0135] Resource usage information includes the usage of terminal CPU, memory, hardware and other resources by the operating system. The less resource usage of the operating system, the better the availability of the operating system.
[0136] The crash information includes the number of crashes within a period of time, which is used to indicate the stability of the operating system. The fewer the number of crashes of the operating system within a period of time, the better the availability of the operating system.
[0137] The software information indicates the compatibility of the operating system. Specifically, the software information includes the compatibility of the operating system with software applications (such as the number and types of compatible software applications). The better the operating system is compatible with software, the better the usability of the operating system.
[0138] The survey information can reflect the usability of the operating system. The model can be used to select samples for targeted user surveys. The users can input the survey information, and the usability of the operating system can be determined based on the survey information and network access time information. The better the usability of the operating system, the better the usability of the operating system.
[0139] The multi-dimensional evaluation indicators determined in step 502 include startup time, resource usage, stability, compatibility, and ease of use. Specifically, the usage information of each terminal operating system is analyzed to determine the multi-dimensional evaluation indicators of each terminal operating system, including:
[0140] Calculate the startup time score of the terminal operating system according to the startup time of the terminal operating system;
[0141] Calculate the resource usage score of the terminal operating system based on the terminal operation resource usage information;
[0142] Calculate the stability score of the terminal operating system based on the terminal operation crash information;
[0143] Calculate the compatibility score of the terminal operating system based on the terminal operating software information;
[0144] The usability score of the terminal operating system is calculated based on the terminal operation survey information and network access time information.
[0145] When step 503 is implemented, the multi-dimensional evaluation indicators of each terminal operating system are grouped according to the operating system and the multi-dimensional evaluation indicators. Each group includes one-dimensional evaluation indicator data of an operating system. The data in each group is averaged to calculate the corresponding dimensional evaluation indicator of the corresponding operating system.
[0146] When step 504 is implemented, the availability of the operating system is calculated using the following formula:
[0147] U i =w1×P i +w2×R i +w3×S i +w4×L i +w5×C i ;
[0148] Among them, U i Score the usability of operating system i, P i Score the startup time of operating system i, R i Score the resource usage of operating system i, S i is the stability score of operating system i, L i Score the usability of operating system i, C i is the compatibility score of operating system i, w1, w2, w3, w4 and w5 are the weights of the corresponding indicators.
[0149] In specific implementation, if stability and resource usage are most important, w2 and w3 are given higher weights. The specific weight values can be customized according to the requirements of the operating system. This article does not limit their specific values.
[0150] This embodiment comprehensively evaluates the availability of the operating system from multiple dimensions, and can give reasonable and accurate operating system purchase recommendations based on the availability of the operating system.
[0151] Based on the same inventive concept, this article also provides a security authentication device compatible with multiple operating systems, as described in the following embodiments. Since the principle of solving the problem by the security authentication device compatible with multiple operating systems is similar to the security authentication method compatible with multiple operating systems, the implementation of the security authentication device compatible with multiple operating systems can refer to the security authentication method compatible with multiple operating systems, and the repeated parts will not be repeated. Specifically, Figure 6 and Figure 7 As shown, the device includes a network access authentication module 601, and the network access authentication module 601 includes:
[0152] The receiving unit 701 is used to receive network access authentication messages sent by terminals of different operating systems;
[0153] The conversion unit 702 is used to parse the network access authentication message sent by each operating system terminal and convert it into a unified authentication message;
[0154] Authentication unit 703, used to perform identity authentication and authority authentication according to the unified authentication message;
[0155] A grouping unit 704 is used to group terminals that have passed identity and authority authentication;
[0156] The control unit 705 is used to control the network access of the terminal according to the firewall and security policy of the group to which the terminal belongs.
[0157] This embodiment converts the network access authentication messages sent by terminals of different operating systems into a unified authentication mode, so that a network access authentication module installed on a security authentication server can realize the unified security authentication and centralized management of terminals of various operating systems, ensure the timeliness and accuracy of network access, and reduce the difficulty of security authentication management of different operating systems. Through the network access control of user groups, personalized control of user network access can be realized, the rationality of network access control can be increased, and the problem of information leakage or resource consumption of network access control can be avoided. At the same time, it can also facilitate the statistics of user behaviors of each group, and provide a basis for the behavior norms of each group of users.
[0158] In one embodiment of this invention, Figure 6 As shown, the multi-operating system compatible security authentication device further includes: a monitoring module 602 for performing user behavior monitoring and system availability monitoring. Specifically, the monitoring module 602 is used to:
[0159] (1) obtaining a terminal network access log; extracting behavior keyword information from the network access log; matching the behavior keyword information with a blacklist database, and issuing an abnormality alarm if the match is successful, wherein the blacklist database includes unauthorized software information and virus information; counting the number of identical behavior keyword information within a predetermined time window, and issuing an abnormality alarm when the number is greater than a predetermined value;
[0160] (2) Counting the number of abnormal times when users use each operating system; counting the total number of times users use each operating system; calculating the violation index of users using each operating system based on the number of abnormal times when users use each operating system and the total number of times the users use each operating system; and generating recommendation information for users to use the operating system based on the violation index of users using each operating system.
[0161] (3) Obtaining usage information of each terminal operating system, wherein the usage information of the terminal operating system includes: startup time, resource usage information, crash information, software information, research information and network access time information; analyzing the usage information of each terminal operating system to determine multiple dimensional evaluation indicators of each terminal operating system; calculating the multiple dimensional evaluation indicators of each operating system based on the multiple dimensional evaluation indicators of each terminal operating system; determining the availability of the operating system based on the multiple dimensional evaluation indicators of each operating system; and generating operating system procurement recommendations based on the availability of the operating system.
[0162] By setting up a monitoring module, this embodiment can achieve the following technical effects:
[0163] (1) Timely discover abnormal behaviors of users in using various operating systems and issue alarms in a timely manner, providing a basis for regulating users' behaviors in using operating systems.
[0164] (2) Comprehensively evaluate the availability of the operating system from multiple dimensions and provide reasonable and accurate operating system procurement recommendations based on the availability of the operating system.
[0165] In one embodiment of the present invention, a computer device is also provided, such as Figure 8As shown, the computer device 802 may include one or more processors 804, such as one or more central processing units (CPUs), each of which may implement one or more hardware threads. The computer device 802 may also include any memory 806, which is used to store any kind of information such as code, settings, data, etc. Non-limitingly, for example, the memory 806 may include any one or more combinations of the following: any type of RAM, any type of ROM, flash memory device, hard disk, optical disk, etc. More generally, any memory may use any technology to store information. Further, any memory may provide volatile or non-volatile retention of information. Further, any memory may represent a fixed or removable component of the computer device 802. In one case, when the processor 804 executes an associated instruction stored in any memory or a combination of memories, the computer device 802 may perform any operation of the associated instruction. The computer device 802 also includes one or more drive mechanisms 808 for interacting with any memory, such as a hard disk drive mechanism, an optical disk drive mechanism, etc.
[0166] The computer device 802 may also include an input / output module 810 (I / O) for receiving various inputs (via input devices 812) and for providing various outputs (via output devices 814). A specific output mechanism may include a presentation device 816 and an associated graphical user interface 818 (GUI). In other embodiments, the input / output module 810 (I / O), input device 812, and output device 814 may not be included, and the computer device 802 may be used as a computer device in a network. The computer device 802 may also include one or more network interfaces 820 for exchanging data with other devices via one or more communication links 822. One or more communication buses 824 couple the components described above together.
[0167] The communication link 822 may be implemented in any manner, for example, through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication link 822 may include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc. governed by any protocol or combination of protocols.
[0168] The embodiments of the present invention further provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are executed.
[0169] The embodiments of this document also provide a computer-readable instruction, wherein when a processor executes the instruction, the program therein causes the processor to execute the method described in any of the aforementioned embodiments.
[0170] It should be understood that in the various embodiments of this document, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this document.
[0171] It should also be understood that in the embodiments of this article, the term "and / or" is only a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0172] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this article.
[0173] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0174] In the several embodiments provided herein, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or can be electrical, mechanical or other forms of connection.
[0175] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiments of this article.
[0176] In addition, each functional unit in each embodiment of this invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or in the form of software functional unit.
[0177] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this article is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of this article. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.
[0178] Specific embodiments are used in this article to illustrate the principles and implementation methods of this article. The description of the above embodiments is only used to help understand the methods and core ideas of this article. At the same time, for general technicians in this field, according to the ideas of this article, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as a limitation on this article.
Claims
1. A security authentication method compatible with multiple operating systems, characterized in that: Applied to a security authentication server, the security authentication server is connected to terminals with different operating systems, and the method includes: Receive network access authentication messages sent by terminals with different operating systems; Parse the network access authentication messages sent by each operating system terminal and convert them into a unified authentication message; Perform identity authentication and authority authentication according to the unified authentication message; Group the terminals that have passed identity and authority authentication; The terminal's access to the network is controlled based on the firewall and security policy of the group to which the terminal belongs.
2. The method according to claim 1, characterized in that The method further comprises: After the terminal successfully accesses the network, the network access time of the user using the terminal is recorded; Calculate the network access time of each operating system used by the user based on the network access time of each terminal and the operating system installed on each terminal; Calculate usage information of each operating system based on the network access time of each operating system used by the user; Generate operating system purchase recommendations based on the usage information of each operating system.
3. The method according to claim 1, characterized in that The method further comprises: Get the terminal network access log; Extract behavioral keyword information from network access logs; Matching the behavior keyword information with the blacklist database, and if the match is successful, issuing an abnormal alarm, wherein the blacklist database includes unauthorized software information and virus information; Count the number of identical behavior keyword information within a predetermined time window, and issue an abnormal alarm when the number is greater than a predetermined value.
4. The method according to claim 3, characterized in that The method further comprises: Count the number of abnormal times users use each operating system; Count the total number of times users use each operating system; Calculate the violation index of the user's use of each operating system according to the abnormal number of times the user uses each operating system and the total number of times the user uses each operating system; Based on the violation indicators of users using each operating system, recommendation information for users to use the operating system is generated.
5. The method according to claim 1, characterized in that The method further comprises: Obtaining usage information of each terminal operating system, wherein the usage information of the terminal operating system includes: startup time, resource usage information, crash information, software information, research information and network access time information; Analyze the usage information of each terminal operating system and determine multiple dimensional evaluation indicators of each terminal operating system; According to the multiple dimensional evaluation indicators of each terminal operating system, the multi-dimensional evaluation indicators of each operating system are calculated; Determine the availability of the operating system based on the evaluation indicators of multiple dimensions of each operating system; Generate operating system purchase recommendations based on operating system availability.
6. The method according to claim 5, characterized in that Analyze the usage information of each terminal operating system and determine the multiple dimensional evaluation indicators of each terminal operating system, including: Calculate the startup time score of the terminal operating system according to the startup time of the terminal operating system; Calculate the resource usage score of the terminal operating system based on the terminal operation resource usage information; Calculate the stability score of the terminal operating system based on the terminal operation crash information; Calculate the compatibility score of the terminal operating system based on the terminal operating software information; The usability score of the terminal operating system is calculated based on the terminal operation survey information and network access time information.
7. The method according to claim 5, characterized in that According to the evaluation indicators of multiple dimensions of each operating system, determining the availability of the operating system includes calculating the availability of the operating system using the following formula: IN i =w1×P i +w2×R i +w3×S i +w4×L i +w5×C i ; Among them, U i Score the usability of operating system i, P i Score the startup time of operating system i, R i Score the resource usage of operating system i, S i is the stability score of operating system i, L i Score the usability of operating system i, C i is the compatibility score of operating system i, w1, w2, w3, w4 and w5 are the weights of the corresponding indicators.
8. A security authentication device compatible with multiple operating systems, characterized in that: Applied to a security authentication server, the security authentication server is connected to terminals with different operating systems, and the device includes: A receiving unit, used to receive network access authentication messages sent by terminals of different operating systems; A conversion unit, used to parse the network access authentication message sent by each operating system terminal and convert it into a unified authentication message; An authentication unit, used to perform identity authentication and authority authentication according to the unified authentication message; A grouping unit, used to group terminals that have passed identity and authority authentication; The control unit is used to control the network access of the terminal according to the firewall and security policy of the group to which the terminal belongs.
9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
10. A computer storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor of a computer device, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Terminal device unified management system and management method based on security module
CN108076135A
Authentication and authorization method and apparatus, authentication server, and machine-readable storage medium
CN108462710A
A method for integrating Linux and Windows operating systems to unify user authentication
CN109829284A
Network access terminal access verification method and device, storage medium and electronic equipment
CN110912938A
Access control method and device, desktop operating system login platform and processor
CN116756776A